CWE-289: Authentication Bypass by Alternate Name
The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.
33 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-29266 — Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication
- CVE-2024-56511 — DataEase has an unauthorized vulnerability
- CVE-2026-8457 — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
- CVE-2026-15980 — MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
- CVE-2025-13613 — Elated Membership <= 1.2 - Authentication Bypass via Social Login
- CVE-2026-9701 — Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
- CVE-2026-24058 — Soft Serve has Critical Authentication Bypass
- CVE-2025-64343 — (conda) Constructor: Excessive permissions during and after installation
- CVE-2024-51996 — Symphony has an Authentication Bypass via RememberMe
- CVE-2026-32036 — OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels
- CVE-2026-56091 — Apache Shiro: Authentication bypass in Guice-Web integration
- CVE-2026-15985 — Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login
- CVE-2026-10842 — IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
- CVE-2026-55075 — Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
- CVE-2026-32639 — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
- CVE-2026-43617 — Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
- CVE-2025-14777 — Keycloak: keycloak idor in realm client creating/deleting
- CVE-2025-64521 — authentik deactivated service accounts can authenticate to OAuth
- CVE-2026-23903 — Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
- CVE-2026-50627 — Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
Recently published
- CVE-2026-15980 — MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
- CVE-2026-32639 — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
- CVE-2026-15985 — Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login
- CVE-2026-8457 — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
- CVE-2026-10842 — IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
- CVE-2026-9701 — Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
- CVE-2026-55075 — Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
- CVE-2026-56091 — Apache Shiro: Authentication bypass in Guice-Web integration
- CVE-2026-50627 — Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
- CVE-2026-43617 — Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
- CVE-2026-32036 — OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels
- CVE-2026-23903 — Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
- CVE-2026-24058 — Soft Serve has Critical Authentication Bypass
- CVE-2025-14777 — Keycloak: keycloak idor in realm client creating/deleting
- CVE-2025-13613 — Elated Membership <= 1.2 - Authentication Bypass via Social Login
- CVE-2025-64521 — authentik deactivated service accounts can authenticate to OAuth
- CVE-2025-64343 — (conda) Constructor: Excessive permissions during and after installation
- CVE-2025-29266 — Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication
- CVE-2024-56511 — DataEase has an unauthorized vulnerability
- CVE-2024-51996 — Symphony has an Authentication Bypass via RememberMe